Chip function configuration method, certificate generation method, related device, medium, and program
By controlling the activation or deactivation of chip functions through certificates, the problem of high chip manufacturing costs is solved, and flexible function adaptation and cost optimization are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HYGON INFORMATION TECH CO LTD
- Filing Date
- 2024-11-01
- Publication Date
- 2026-05-08
AI Technical Summary
In the existing technology, designing and producing chips with different functions to meet different user needs increases manufacturing costs, and users cannot flexibly change the chip functions to adapt to changes in demand.
The activation or deactivation of chip functions is controlled by certificates. Users can update chip functions by updating certificates, achieving flexible function adaptation.
This reduces chip manufacturing costs, allowing users to adapt to changing needs without purchasing new chips or returning them for upgrades, thus improving the flexibility of chip function configuration.
Smart Images

Figure CN121996607A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of chip technology, specifically to a chip function configuration, certificate generation method, related apparatus, medium, and program. Background Technology
[0002] Processor chips and System-on-Chips (SoCs) are widely used in gaming, artificial intelligence, terminal devices (such as mobile devices), and servers (such as enterprise servers). As user needs diversify, chip functionality needs to be adjusted to meet those needs; for example, chips with customized functions need to be provided based on specific user requirements.
[0003] However, designing and manufacturing chips with different functions to meet diverse user needs would undoubtedly increase chip manufacturing costs significantly. Therefore, how to provide technical solutions that flexibly offer chips with functions adapted to user requirements has become a pressing technical problem for those skilled in the art. Summary of the Invention
[0004] In view of this, embodiments of this application provide a chip function configuration, a certificate generation method, related devices, media, and program to flexibly provide chips with functions adapted to user needs.
[0005] To achieve the above objectives, the embodiments of this application provide the following technical solutions.
[0006] In a first aspect, embodiments of this application provide a chip function configuration method, applied to a chip, the method comprising:
[0007] Obtain the certificate to be imported. The certificate includes a verification field containing verification information and multiple function setting fields configured with switch status values. One of the function setting fields corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field.
[0008] Based on the verification information, verify whether the certificate passes.
[0009] If the certificate is verified successfully, the certificate is imported, and the on / off state of the chip function corresponding to the function setting field in the certificate is configured according to the on / off state value.
[0010] Secondly, embodiments of this application provide a certificate generation method applied to manufacturer equipment, the method comprising:
[0011] Determine the functional requirements information of the chip, which includes the on / off states of multiple chip functions;
[0012] Based on the required on / off states of multiple chip functions, configure the on / off state values of multiple function setting fields in the certificate so that the on / off state values of multiple function setting fields correspond to the required on / off states of multiple chip functions, wherein one function setting field corresponds to one chip function.
[0013] Determine the chip's verification information and write it into the certificate's verification field.
[0014] Thirdly, embodiments of this application provide a chip function configuration device, including:
[0015] The certificate acquisition module is used to acquire the certificate to be imported. The certificate includes a verification field containing verification information and multiple function setting fields configured with switch status values. One of the function setting fields corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field.
[0016] The verification module is used to verify whether the certificate passes based on the verification information.
[0017] The function configuration module is used to import the certificate if the certificate is verified, and configure the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value of the function setting field in the certificate.
[0018] Fourthly, embodiments of this application provide a certificate generation apparatus, comprising:
[0019] A functional requirement determination module is used to determine the functional requirement information of the chip, which includes the on / off states of multiple chip functions.
[0020] The function setting field configuration module is used to configure the on / off state values of multiple function setting fields of the certificate according to the required on / off state of multiple chip functions, so that the on / off state values of multiple function setting fields correspond to the required on / off state of multiple chip functions, wherein one function setting field corresponds to one chip function.
[0021] The verification field configuration module is used to determine the chip's verification information and write the verification information into the certificate's verification field.
[0022] Fifthly, embodiments of this application provide a chip including processor firmware, the processor firmware being configured to execute the chip function configuration method as described in the first aspect above.
[0023] In a sixth aspect, embodiments of this application provide a manufacturer's device, including a memory and a processor, wherein the memory stores computer instructions, and the processor invokes the computer instructions stored in the memory to execute the certificate generation method as described in the second aspect above.
[0024] In a seventh aspect, embodiments of this application provide a storage medium that stores computer instructions. When the computer instructions are executed, they implement the chip function configuration method as described in the first aspect above, or the certificate generation method as described in the second aspect above.
[0025] Eighthly, embodiments of this application provide a computer program product, including computer instructions, which, when executed, implement the chip function configuration method as described in the first aspect above, or the certificate generation method as described in the second aspect above.
[0026] In the chip function configuration method provided in this application embodiment, the chip can obtain a certificate to be imported. The certificate includes a verification field containing verification information and multiple function setting fields configured with switch status values. Each function setting field corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field. Therefore, the chip can verify whether the certificate passes the verification based on the verification information in the certificate. If the certificate passes the verification, the chip can import the certificate and then configure the switch status of the chip function corresponding to the function setting field in the chip according to the switch status value of the function setting field in the certificate. It can be seen that this application embodiment supports configuring the switch status of chip functions in the chip through a certificate. That is, the switch status value of the function setting field in the certificate can configure the switch status of the chip function corresponding to the function setting field. Thus, the user can obtain a certificate whose switch status of the chip function meets the user's needs and import it into the chip to configure the activated or deactivated chip functions in the chip according to the certificate, thus meeting the user's needs. In other words, the solution provided in this application allows users to flexibly select chip certificates according to their needs, and flexibly configure the on / off state of chip functions when the certificate verification is successful, thereby flexibly providing chips with functions adapted to user needs and improving the flexibility of chip function configuration while meeting user needs. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0028] Figure 1A An example diagram of the certificate format provided in this application embodiment.
[0029] Figure 1B Example diagrams illustrating the content and description of the certificate provided in this application embodiment.
[0030] Figure 2 A flowchart illustrating certificate generation provided in this application embodiment.
[0031] Figure 3 A flowchart illustrating the chip function configuration provided in the embodiments of this application.
[0032] Figure 4 An example diagram illustrating the incremental activation mode of chip functionality provided in this application embodiment.
[0033] Figure 5 Example diagrams illustrating the activation and deactivation of chip functions provided in embodiments of this application.
[0034] Figure 6 This is an example diagram illustrating the format of the functional support data provided in the embodiments of this application.
[0035] Figure 7 A flowchart illustrating the chip function configuration that supports power-down restart provided in the embodiments of this application.
[0036] Figure 8 This is a block diagram of a chip function configuration device provided in an embodiment of this application.
[0037] Figure 9 A block diagram of a certificate generation apparatus provided in an embodiment of this application. Detailed Implementation
[0038] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0039] To reduce chip design and manufacturing costs, chip manufacturers can design a single hardware chip design and then program it to customize different functions, thus meeting diverse user needs. In other words, a chip with the same hardware design can be programmed to perform different functions to serve varying user requirements (e.g., catering to different customer groups and markets), thereby avoiding the need to design and manufacture separate chips for different user needs and reducing chip manufacturing costs.
[0040] One way to customize chips with different functions through programming is to enable or disable specific chip functions by programming. For example, for a certain chip function, the chip function can be enabled or disabled by programming, thereby customizing the chip to enable or disable the chip function.
[0041] An eFuse (electronic fuse) is a programmable fuse that can permanently disconnect or connect the functional circuitry of a chip, thereby changing the chip's hardware configuration and enabling or disabling specific chip functions. For example, to enable a chip function, the eFuse can permanently connect the functional circuitry for that function; conversely, to disable a chip function, the eFuse can permanently disconnect the functional circuitry for that function.
[0042] However, the method of customizing chips with different functions through eFuse programming still suffers from a lack of flexibility, specifically:
[0043] Once the chip leaves the factory, the chip functions that are enabled or disabled through eFuse programming are permanently locked. Users cannot change the enabled or disabled chip functions through subsequent software upgrades. This means that if user needs change, users can only choose to purchase a new chip that meets their changing needs, or return the chip to the factory for an upgrade with the support of the chip manufacturer.
[0044] Based on this, embodiments of this application provide an improved chip function configuration scheme. This scheme can be a certificate-based chip function customization scheme, where certificates control the activation or deactivation of chip functions. Furthermore, the scheme allows users to update activated or deactivated chip functions by updating certificates, thus flexibly providing chips with functions adapted to user needs. In other words, if user needs change, users can update activated or deactivated chip functions by choosing to update certificates to adapt to changing requirements. Users do not need to purchase new chips or return chips for upgrades, thereby improving the flexibility of customizing chips with different functions and adapting to user needs.
[0045] As an optional implementation Figure 1A An exemplary diagram illustrating the certificate format provided in this application is shown, such as... Figure 1A As shown, the certificate format may include: a chip identification field, multiple function setting fields, and a certificate signature field.
[0046] The chip identifier field is the field corresponding to the chip identifier information in the certificate, used to write the chip identifier information. The chip identifier information is used to uniquely identify the chip on which the certificate is installed, thereby ensuring that the certificate can be uniquely installed on the chip corresponding to the chip identifier information of the certificate. In other words, the certificate is installed on the chip corresponding to the chip identifier information carried by the certificate, which can prevent the misuse of the certificate (i.e., prevent the certificate from being installed on a chip that does not correspond to the chip identifier information of the certificate), and ensure the legitimacy of the certificate installation.
[0047] In an optional implementation, the chip identification information can be a chip serial number, which is a unique identifier for the chip to distinguish different chips.
[0048] The FEATURE SETTING field is used to identify the chip's chip functions. Based on the chip's multiple chip functions, the certificate can have multiple FEATURE SETTING fields corresponding to multiple chip functions. For example, one FEATURE SETTING field corresponds to one chip function.
[0049] In an optional implementation, the multiple chip functions corresponding to the multiple function setting fields of the certificate can be: multiple chip functions whose switch states can be controlled. The switch states of the chip functions can be divided into active state (i.e., the chip function is activated or turned on) and closed state (i.e., the chip function is turned off).
[0050] As an optional implementation, any chip function whose switching state can be controlled can have its corresponding function setting field configured in the certificate. For example, combined with Figure 1A As shown, if a chip has n independently controllable chip functions (i.e., the n chip functions of the chip can be independently controlled to switch on / off), then the certificate's multiple function setting fields can be n function setting fields, such as function setting field 1 (FEATURE1_SETTING) to function setting field n (FEATUREn_SETTING), so that the n independently controllable chip functions can be covered by n function setting fields, and one function setting field corresponds to one chip function.
[0051] For example, the chip's hardware design can incorporate multiple independently controllable chip functions, such as graphics processing, encryption / decryption, network communication, and TKM (Trusted Key Management Module) functions. In other words, these chip functions can be independently controlled to be activated or deactivated as needed to meet different user requirements. Therefore, the graphics processing, encryption / decryption, network communication, and TKM functions, whose on / off states can be independently controlled, can each have their corresponding function setting fields configured in the certificate.
[0052] In an optional implementation, the on / off state value of the function setting field can indicate the on / off state of the chip function corresponding to the function setting field, that is, the on / off state value of the function setting field can indicate whether the chip function corresponding to the function setting field is active or closed.
[0053] In the optional implementation example, if the on / off state value of the function setting field is the first value, it means that the on / off state of the chip function corresponding to the function setting field is active; if the on / off state value of the function setting field is the zeroth value, it means that the on / off state of the chip function corresponding to the function setting field is closed.
[0054] For example, taking function setting field 1 (FEATURE1_SETTING) corresponding to chip function 1 and function setting field 2 (FEATURE2_SETTING) corresponding to chip function 2 as examples, if the on / off state value of function setting field 1 is the first value, such as FEATURE1_SETTING = 1, then the on / off state of chip function 1 is active, meaning chip function 1 is activated and turned on. If the on / off state value of function setting field 2 is the zeroth value, such as FEATURE2_SETTING = 0, then the on / off state of chip function 2 is deactivated, meaning chip function 2 is turned off. Therefore, by adjusting the on / off state values of function setting field 1 (FEATURE1_SETTING) and function setting field 2 (FEATURE2_SETTING) in the certificate, the on / off state of chip function 1 and chip function 2 can be adjusted to meet user needs.
[0055] For example, if the user requires chip function 1 to be enabled and chip function 2 to be disabled, then the certificate can be configured as follows:
[0056] FEATURE1_SETTING=1, and FEATURE2_SETTING=0;
[0057] For example, if the user requires that chip function 1 is disabled and chip function 2 is enabled, then the certificate can be configured as follows:
[0058] FEATURE1_SETTING=0, and FEATURE2_SETTING=1.
[0059] The certificate signature field is the field corresponding to the certificate signature information (SIGNATURE) in the certificate, used to write the certificate signature information. The certificate signature information can be a digital signature of the certificate, for example, a digital signature of the certificate generated through an encryption algorithm, used to verify the authenticity and integrity of the certificate. In an optional implementation, this embodiment of the application includes the chip identification information (e.g., chip serial number) in the certificate, and combines it with the digital signature of the certificate, which can bind each certificate to a unique chip and prevent the certificate content from being illegally tampered with, ensuring the security and reliability of the certificate.
[0060] In a further optional implementation, the certificate may also include version information, such as the certificate version number (VERSION), to ensure certificate compatibility and that the certificate content can be correctly parsed.
[0061] For example, let's take a certificate setting with n function setting fields, corresponding to n chip functions. Figure 1B An example diagram illustrating the content and description of the certificate provided in this application is shown below and can be referred to in conjunction with the above description.
[0062] It should be noted that the chip identifier field and certificate signature field can be used as verification fields for certificates, where verification information is written. For example, the verification information can include the chip identifier information written in the chip identifier field and the certificate signature information written in the certificate signature field. Furthermore, the verification information used by the certificate is not limited to chip identifier information and certificate signature information. For example, certificates can also use timestamps, usage permission information, etc., as verification information. Correspondingly, the verification fields used by the certificate can also include timestamp fields, usage permission information fields, etc. For example, a certificate can include a timestamp to indicate the issuance and / or expiration date of the certificate, preventing the use of expired or invalid certificates; for example, a certificate can include usage permission information to limit the scope of devices and users from which the certificate can be used, preventing the certificate from being used on unauthorized devices or by unauthorized users.
[0063] The verification information and corresponding verification fields used in the certificate can be determined according to the actual situation, and the embodiments in this application are not limited to the examples above.
[0064] In an optional implementation, the certificate can be generated by the chip manufacturer's equipment (hereinafter referred to as the manufacturer's equipment), and the certificate generated by the manufacturer's equipment can be imported into the chip. The chip with the imported certificate can be installed in user-used electronic devices such as terminal devices (e.g., mobile devices), servers (e.g., enterprise-level servers). The solutions provided by the embodiments of this application are described below from the perspectives of certificate generation and certificate import. Certificate generation mainly involves the process of the manufacturer's equipment generating a certificate; certificate import mainly involves the process of importing the certificate into the chip and configuring the on / off state of the chip's functions according to the certificate.
[0065] As an optional implementation Figure 2 An exemplary flowchart of an optional certificate generation process provided in an embodiment of this application is illustrated. This process can be executed by a vendor's device, which can be, for example, a server used by a chip manufacturer (i.e., a vendor server), or a server used by a CPU (Central Processing Unit) manufacturer. (Refer to...) Figure 2 The process may include the following steps.
[0066] In step S210, the chip identification information and the functional requirement information of the chip are determined. The functional requirement information includes the on / off states of multiple chip functions.
[0067] In an optional implementation, the chip's functional requirement information can indicate multiple chip functions and whether each function needs to be enabled or disabled; that is, the chip's functional requirement information can indicate the on / off status of multiple chip functions. Alternatively, the chip's functional requirement information can be file information, recording the function identifiers (such as function identifiers or names) for each of the chip's multiple chip functions, and the on / off status of each function identifier (i.e., whether the chip function corresponding to each function identifier needs to be enabled or disabled).
[0068] In an optional implementation, this application embodiment supports pre-generating multiple certificates for the chip. For example, chip manufacturers can use their equipment to pre-generate a series of certificates for the chip during chip manufacturing. Each certificate contains different functional configurations, allowing users to select the chip's certificate as needed. As an optional implementation, in the case of pre-generating multiple certificates for the chip, this application embodiment can pre-set multiple functional requirement information for the chip (for ease of explanation, the pre-set functional requirement information for the chip is referred to as the chip's preset functional requirement information). For example, chip manufacturers can pre-define multiple functional configuration schemes for the chip based on different usage scenarios and market demands. Thus, one functional configuration scheme of the chip can correspond to one preset functional requirement information of the chip. Furthermore, one preset functional requirement information of the chip can include multiple preset requirement on / off states of chip functions, and the preset requirement on / off states of multiple chip functions indicated by different preset functional requirement information of the chip are different. For example, different functional configuration schemes of the chip correspond to different chip functions being enabled or disabled.
[0069] Based on this, when multiple certificates for the chip are pre-generated, the functional requirement information of the chip determined in step S210 can be any one of multiple preset functional requirement information pre-set for the chip. Therefore, during chip manufacturing, this embodiment can determine the chip identification information (e.g., chip serial number) and select any one of the multiple preset functional requirement information from the chip's preset functional requirement information. In other words, this embodiment can be based on... Figure 2 The proposed solution generates a chip certificate in advance for each preset functional requirement information of the chip, thereby generating multiple certificates for the chip in advance (for ease of explanation, the chip certificate generated in advance by the manufacturer's equipment can be called a preset certificate). For example, each preset functional requirement information of the chip can correspond to a preset certificate generated for the chip, thus obtaining multiple preset certificates for the chip.
[0070] In other optional implementations, embodiments of this application support dynamically generating chip certificates. For example, a manufacturer's device can dynamically generate a chip certificate based on user requirements, making the chip certificate adaptable to specific user needs. For instance, a chip manufacturer can receive user requirement information, which may specify chip identification information (such as a chip serial number) and functional requirements of the chip. The chip manufacturer can then generate a chip certificate based on the received specific user requirement information, ensuring that the generated chip certificate meets the user's personalized needs.
[0071] As an optional implementation, in the case of dynamically generated chip certificates, the user requirement information can carry the chip identification information and the functional requirement information specified by the user. This allows the user to provide the user requirement information to the chip manufacturer's equipment, enabling the manufacturer's equipment to determine the chip identification information and the chip's functional requirement information in step S210. In other words, in the case of dynamically generated chip certificates, the chip's functional requirement information can be user-provided functional requirement information, adapted to specific user needs. For ease of explanation, the functional requirement information carried in the user requirement information (i.e., the user-provided functional requirement information) is referred to in this embodiment as the chip's specified functional requirement information. The specified functional requirement information can include the specified on / off states of multiple chip functions specified by the user.
[0072] Based on this, in the case of dynamically generated chip certificates, the chip identification information determined in step S210 can be: the chip identification information carried in the user requirement information. For example, when a user requests the manufacturer's equipment to generate a chip certificate, they can provide the manufacturer's equipment with user requirement information carrying the chip serial number to indicate the chip for which a certificate needs to be generated. The chip functional requirement information determined in step S210 can be: specified functional requirement information carried in the user requirement information. For example, when a user requests the manufacturer's equipment to generate a chip certificate, they can provide the manufacturer's equipment with user requirement information carrying specified functional requirement information to indicate the on / off status of multiple chip functions required by the user.
[0073] In step S211, the chip identification information of the chip is written into the chip identification field of the certificate.
[0074] In step S212, the switch status values of multiple function setting fields of the certificate are configured according to the required switch status of multiple chip functions, so that the switch status values of multiple function setting fields correspond to the required switch status of multiple chip functions, wherein one function setting field corresponds to one chip function.
[0075] In an optional implementation, steps S211 and S212 can be executed simultaneously.
[0076] As mentioned earlier, a certificate can have multiple function setting fields corresponding to multiple chip functions, and one function setting field corresponds to one chip function. After obtaining the functional requirement information of the chip, the manufacturer's equipment can configure the on / off status values of multiple function setting fields in the certificate based on the on / off status of the multiple chip functions indicated by the functional requirement information, so that the on / off status value of each function setting field corresponds to the on / off status of the chip function corresponding to the function setting field, thereby realizing the configuration of multiple function setting fields in the certificate.
[0077] In an optional implementation, if the on / off state value of the function setting field is the first value (e.g., 1), the corresponding chip function is in an active state, and the on / off state value of the function setting field is the zeroth value (e.g., 0), the corresponding chip function is in a closed state. For example, if the chip's function requirement information indicates that chip function 1 is on and chip function 2 is off, then the on / off state value of the function setting field 1 corresponding to chip function 1 in the certificate can be configured to be 1, i.e., FEATURE1_SETTING = 1, and the on / off state value of the function setting field 2 corresponding to chip function 2 in the certificate can be configured to be 0, i.e., FEATURE1_SETTING = 0.
[0078] In step S213, based on the chip identification information written in the chip identification field of the certificate and the switch status values of multiple function setting fields, the certificate signature information is determined using the chip manufacturer's private key, and the certificate signature information is written into the certificate signature field of the certificate.
[0079] As an optional implementation, after writing the chip identification information of the chip into the chip identification field of the certificate and configuring the on / off status values of multiple function setting fields of the certificate, in order to facilitate the verification of the authenticity and integrity of the certificate, this embodiment of the application can further generate certificate signature information and write the certificate signature information into the certificate signature field of the certificate.
[0080] In an optional implementation, the certificate signature information can be a digital signature generated using an encryption algorithm, used to verify the authenticity and integrity of the certificate. This allows the certificate issuer's private key to generate the signature information, which can then be verified using the corresponding public key. This ensures the certificate is protected from unauthorized tampering after generation, guaranteeing its security. It's important to note that the private key is part of the asymmetric encryption technology used in digital signatures and encrypted communication. Asymmetric encryption involves a key pair (private and public keys), where the private key is kept secret and held by the certificate issuer (e.g., a chip manufacturer). Therefore, the certificate issuer's private key used for signing could be, for example, the chip manufacturer's private key, or the CPU manufacturer's private key.
[0081] In an optional implementation, the vendor device can generate certificate signature information for the certificate using the chip identifier information written in the chip identifier field of the certificate and the on / off status values of multiple function setting fields, using the chip vendor's private key. For example, the private key can be used to encrypt the hash value of the data to be signed, thereby generating a digital signature. In this example, the vendor device can collect the chip identifier information written in the chip identifier field of the certificate and the on / off status values of multiple function setting fields, and organize them into data to be signed. Then, the data to be signed (such as the chip identifier information and the on / off status values of each function setting field) is hashed to obtain the hash value of the data to be signed. For example, a hash function can be used to calculate a fixed-length hash value (e.g., a hash value) corresponding to the data to be signed. At this point, the hash value of the data to be signed can uniquely represent the content of the data to be signed; that is, any change in the content of the data to be signed will cause a change in the hash value. For example, a change in the chip identifier information or a change in the on / off status value of any function setting field will cause a change in the hash value. Then, by encrypting the hash value of the data to be signed using the chip vendor's private key, the certificate signature information of the certificate can be obtained. In other words, when a chip manufacturer needs to generate a certificate for a chip, it can use the chip manufacturer's private key to encrypt the hash value of the content already set in the certificate (chip identification information and the on / off status values of each function setting field). The encrypted hash value can then constitute the certificate signature information of the certificate, and the certificate signature information is written into the certificate signature field of the certificate.
[0082] In an optional implementation, after writing chip identification information in the chip identification field of the certificate, writing certificate signature information in the certificate signature field of the certificate, and configuring switch status values in multiple function setting fields of the certificate, this embodiment of the application can obtain the chip certificate by combining the version information of the certificate (e.g., version number).
[0083] Furthermore, based on the embodiments of this application supporting multiple certificates pre-generated for the chip, the embodiments of this application can... Figure 2 The method shown generates multiple preset certificates for a chip based on multiple preset functional requirement information of the chip. For example, for any given chip, the chip identification information (such as the serial number) is the same, and the different preset certificates of the chip correspond to different preset functional requirement information of the chip. Thus, multiple preset functional requirement information of the chip can be used to generate multiple preset certificates for the chip.
[0084] Furthermore, based on the fact that this application embodiment supports dynamically generated chip certificates, this application embodiment can... Figure 2The method shown generates a chip certificate based on user-provided specified functional requirement information. For ease of explanation, the certificate generated by the manufacturer's equipment based on the specified functional requirement information can be called a specified certificate; that is, the manufacturer's equipment can generate a specified certificate for the chip, and the specified certificate for the chip corresponds to the user-provided specified functional requirement information.
[0085] It should be noted that, Figure 2 The chip identification information and certificate signature information in the example are merely optional implementations of the verification information in the certificate. Correspondingly, the chip identification field and certificate signature field are only optional implementations of the verification fields in the certificate. In other words, when generating a chip certificate in this embodiment, the on / off state values of multiple function setting fields in the certificate are configured based on the chip's functional requirements information. The chip's verification information is written into the certificate's verification fields, thus forming a chip certificate from the verification field containing the verification information and the multiple function setting fields configured with on / off state values. In other possible alternative implementations, such as when using timestamps, usage permission information, or other forms of verification information, the certificate can also have corresponding other forms of verification fields, and is not limited to these. Figure 2 The example shows the chip identification field and certificate signature field, i.e. Figure 2 The certificate generation method shown, which uses chip identification information and certificate signature information as verification information, is only an example of how to generate a certificate.
[0086] Based on the chip certificate generated by the manufacturer's equipment (such as a preset certificate or a specified certificate), electronic devices equipped with the chip (such as terminal devices or servers) can obtain the chip certificate generated by the manufacturer's equipment and import the certificate after successful verification to configure the on / off state of the chip's functions according to the certificate. Based on this, as an optional implementation, Figure 3 An exemplary flowchart of an optional chip function configuration provided in an embodiment of this application is shown. This process can be executed by a chip loaded into an electronic device, specifically by the chip's processor firmware (such as CPU firmware). (Refer to...) Figure 3 The process may include the following steps.
[0087] In step S310, the certificate to be imported is obtained.
[0088] In an optional implementation, the certificate to be imported can be a preset certificate selected from multiple preset certificates for the chip. For example, if the chip manufacturer pre-generates multiple preset certificates for the chip, the user can select a preset certificate that suits their needs from the multiple preset certificates provided by the chip manufacturer as the certificate to be imported.
[0089] For example, a chip manufacturer can pre-generate multiple preset certificates for the chip and provide a certificate service. This certificate service can be an online service (e.g., an online service for selecting and deploying preset certificates for chip function configuration). The chip manufacturer can provide a certificate service selection page that displays information about the multiple preset certificates (e.g., the on / off status of chip functions corresponding to each preset certificate) and selection options for each preset certificate. Users can then browse this selection page using an electronic device equipped with the chip and confirm their selection from the multiple preset certificate options. The preset certificate selected by the user can be the one chosen from the multiple preset certificates for the chip. The chip manufacturer's device can then send the user-selected preset certificate to the electronic device equipped with the chip, allowing the chip to obtain the certificate to be imported.
[0090] In other possible examples, chip manufacturers can pre-generate multiple preset certificates for the chip and provide certificate services. The certificate service can be an offline service. For example, the chip manufacturer can learn about the preset certificate selected by the user offline or online, and then use the preset certificate selected by the user as the certificate to be imported and write it to physical media (such as USB drive, optical disc, etc.). After the user obtains the physical media, he / she can use the electronic device with the chip installed to read the physical media and obtain the preset certificate selected by the user.
[0091] In an optional implementation, the certificate to be imported can be a specific certificate for the chip. For example, after providing specific functional requirements to the chip manufacturer, the user can obtain a specific certificate generated by the chip manufacturer for the corresponding chip, which can then be used as the certificate to be imported. For instance, the chip manufacturer can provide a certificate service, which can be offered as an online service. The chip manufacturer can provide a customized service page for the certificate service. This customized service page allows the user to input the chip identification information of the chip to be customized, as well as the on / off states of multiple chip functions to be customized. The user can then use an electronic device equipped with the chip to browse this customized service page, inputting the chip identification information and the on / off states of multiple chip functions (i.e., the specific functional requirements provided by the user), and organizing this into user requirement information. The electronic device equipped with the chip can then provide the user requirement information to the chip manufacturer's equipment, which can then generate the specific certificate for the chip and send it back to the electronic device equipped with the chip, enabling the chip to obtain the certificate to be imported.
[0092] In other possible examples, chip manufacturers can provide certificate services, which can be an offline service. For example, chip manufacturers can learn about user needs (including chip identification information and user-provided specific functional requirements) offline or online, and then generate a specific certificate for the chip according to the user's needs and write it to the physical medium. After obtaining the physical medium, the user can use an electronic device with the chip installed to read the physical medium and obtain the specific certificate that meets the user's specified functional requirements.
[0093] Furthermore, the aforementioned certificate service can be a paid service. For example, users can choose to purchase a pre-set certificate that meets their needs from multiple pre-set certificates for the chip, or purchase a specific certificate for a customized chip through the certificate service. For instance, after a user selects a pre-set certificate, the chip manufacturer can select the corresponding pre-set certificate and provide it to the user after receiving the user's purchase request; similarly, when a user purchases a specific certificate for a customized chip, the user can provide the chip identification information and specified functional requirements to the chip manufacturer. The chip manufacturer, after receiving the user's purchase request, can then generate the specified certificate for the chip based on the provided chip identification information and specified functional requirements and provide it to the user.
[0094] In the optional implementation, based on Figure 1A The example certificate format; certificates to be imported may include:
[0095] The chip identification field contains chip identification information, which is used to identify the chip corresponding to the certificate, that is, to identify the chip that can legally import the certificate;
[0096] Multiple function setting fields, where each function setting field corresponds to a chip function, and the on / off status value of the function setting field indicates the on / off status of the chip function corresponding to the function setting field;
[0097] The certificate signature field contains the certificate signature information, which is used to verify the authenticity and integrity of the certificate.
[0098] It should be noted that the chip identification information and certificate signature information are only optional examples of certificate verification information; correspondingly, the chip identification field and certificate signature field are only optional examples of certificate verification fields. For ease of explanation, Figure 3 The following example process is based on Figure 1A The example certificate format is explained.
[0099] In step S311, the public key of the chip manufacturer is used to verify whether the certificate signature information is valid. If not, step S312 is executed; if yes, step S313 is executed.
[0100] In an optional implementation, the chip (e.g., the chip's processor firmware) obtains the certificate to be imported and can verify the certificate signature information in the certificate before importing it. For example, in this embodiment, the certificate signature information can be extracted from the certificate signature field of the certificate, and the chip manufacturer's public key can be used to verify the certificate signature information, i.e., verify whether the certificate signature information passes the verification. If the verification fails (i.e., the certificate signature information is not verified), it means that the certificate is invalid, such as the content of the certificate has been illegally tampered with. In this case, this embodiment can end the process. If the verification succeeds (i.e., the certificate signature information is verified), it means that the certificate is valid, such as the content of the certificate has not been illegally tampered with. In this case, this embodiment can continue the subsequent process.
[0101] As an optional implementation, the certificate signature information can be a digital signature generated by an encryption algorithm. The private key is used to encrypt the certificate signature information, and the public key is used to decrypt the encrypted certificate signature information. Then, the chip identification information and the on / off status values of each function setting field in the certificate can form the data to be signed. The private key can then encrypt the hash value of the data to be signed to form the certificate signature information. Based on this, the verification of whether the certificate signature information is valid can be achieved by comparing the hash value obtained by decrypting the certificate signature information with the recalculated hash value.
[0102] In an optional implementation example, this application embodiment can use the chip manufacturer's public key to decrypt the certificate signature information to obtain the decrypted hash value; and extract the chip identification information of the chip identification field of the certificate and the on / off status values of multiple function setting fields to form the certificate's data to be signed, and calculate the hash value corresponding to the certificate's data to be signed to obtain the calculated hash value; then, compare the decrypted hash value with the calculated hash value; if the comparison result is consistent, it means that the certificate has not been tampered with and the certificate was issued by the chip manufacturer holding a legitimate private key, and the certificate is considered valid and the signature verification is successful; if the comparison result is inconsistent, it means that the certificate may have been illegally tampered with after digital signing, or the digital signature was not issued by the chip manufacturer holding a legitimate private key, and the certificate is considered invalid and the signature verification fails.
[0103] It should be noted that the private key of the chip manufacturer used to generate the certificate signature information (such as the private key of the CPU manufacturer) is kept confidential and is held only by the certificate issuer (such as the chip manufacturer); while the chip manufacturer's public key corresponds to the private key, and the chip manufacturer's public key can be made public, so that users can use the publicly available chip manufacturer's public key to verify the authenticity of the certificate signature information.
[0104] In step S312, the process ends.
[0105] In the event of signature verification failure, this embodiment of the application can terminate the process. Furthermore, in the event of signature verification failure, this embodiment of the application can also provide an error report, which can indicate the cause of the error.
[0106] In step S313, check whether the chip identification information matches the chip of the certificate to be imported. If not, proceed to step S312; if yes, proceed to step S314.
[0107] As an optional implementation, upon successful signature verification, the chip (e.g., the chip's processor firmware) can check the chip identification information in the certificate. For example, in this embodiment, the chip identification information can be extracted from the chip identification field of the certificate, and the chip identification information can be checked to see if it matches the chip of the certificate to be imported. If the chip identification information does not match the chip of the certificate to be imported, it indicates that the certificate is not designed for the current chip, that is, the chip that can legally install the certificate is not the chip of the certificate to be imported. In this case, the certificate is considered invalid, and the process can end in this embodiment. If the chip identification information matches the chip of the certificate to be imported, it indicates that the certificate can be legally installed on the chip of the certificate to be imported, and the subsequent process can continue in this embodiment.
[0108] In an optional implementation, this embodiment of the application can check whether the chip identification information in the certificate is consistent with the chip identification information of the chip to be imported into the certificate. For example, after the certificate signature information is successfully verified, the next step in this embodiment of the application can be to check the chip serial number (an example of chip identification information) in the certificate, that is, to check whether the chip serial number in the certificate is consistent with the chip serial number of the chip to be imported into the certificate. If the check results are consistent, the chip identification information in the certificate matches the chip of the current certificate to be imported into the certificate. If the check results are inconsistent, the chip identification information in the certificate does not match the chip of the current certificate to be imported into the certificate.
[0109] This application embodiment ensures the authenticity and integrity of the certificate content through the verification process of the certificate signature information; and ensures the uniqueness and security of the certificate when imported and installed on a legitimate chip through the checking process of the chip identification information. In other words, the certificate is designed for the chip corresponding to the chip identification information in the certificate. Only when the chip identification information in the certificate matches the chip identification information of the chip to be imported is the certificate considered valid and can be successfully imported into the chip. This means that a legitimate certificate for one chip cannot be used for another chip, ensuring the certificate's exclusivity and security. Furthermore, if a user wants to enable the same chip functionality on different chips, based on the different chip identification information of different chips, the user needs to obtain corresponding certificates for each chip separately to prevent unauthorized certificate use.
[0110] In step S314, the on / off state of the chip function corresponding to the function setting field is configured according to the on / off state value of the function setting field in the certificate.
[0111] If the certificate signature information is successfully verified and the chip identification information is checked, the certificate verification is successful, and the chip is successfully imported with the certificate. In this embodiment, after the chip is successfully imported with the certificate, the switch status values of multiple function setting fields of the certificate can be used to configure the switch status of the chip function corresponding to the function setting field, so as to configure the switch status of the chip function according to the certificate.
[0112] It should be noted that the certificate signature information and chip identification information shown above are only optional examples of the verification information used in the certificate. That is, the certificate may include verification information written in the verification field, and the on / off status values of multiple function setting fields. In this embodiment, after obtaining the certificate, the verification information can be extracted from the verification field in the certificate, and the certificate can be verified based on the verification information. If the certificate verification is successful, the chip successfully imports the certificate, and step S314 is executed; if the certificate verification fails, step S312 is executed to end the process. Furthermore, in implementing the certificate verification, this embodiment can use different forms of verification information, and is not limited to these. Figure 3 The example certificate signature information and chip identification information, such as those mentioned earlier, mean that the verification information in the certificate can take different forms, thus... Figure 3 The certificate verification process described in the example is merely an optional example; in possible alternative implementations, verification information in the certificate can include timestamps, usage permission information, etc., based on other forms of verification information such as timestamps and usage permission information in the certificate. Therefore, the embodiments of this application can also use verification information such as timestamps and usage permission information in the certificate for certificate verification, and are not limited to this. Figure 3 The example uses certificate signature information and chip identification information to verify the certificate.
[0113] This application embodiment does not limit the certificate verification method, and after the certificate verification is successful, the chip can import the certificate (i.e., the chip successfully imports the certificate at this time). Therefore, this application embodiment can control the on / off state of the chip function corresponding to the function setting field based on the on / off state value of the function setting field in the certificate. For example, if the on / off state value of any function setting field in the certificate indicates an active state (e.g., the on / off state value of the function setting field is the first value), then the chip function corresponding to the function setting field in the configuration chip is activated, that is, the chip function corresponding to the function setting field is controlled to be in an active state. For example, if the on / off state value of any function setting field in the certificate indicates a closed state (e.g., the on / off state value of the function setting field is the zeroth value), then the chip function corresponding to the function setting field is closed, that is, the chip function corresponding to the function setting field is controlled to be in a closed state.
[0114] In the optional implementation, the on / off states of multiple chip functions configured by the chip can be categorized as follows:
[0115] Scenario 1: Incremental activation of chip functions. For example, in this embodiment, the already activated chip functions can be maintained, and the function setting field whose switch state value in the certificate indicates the activated state can be determined. The chip function corresponding to the function setting field whose switch state value indicates the activated state can be activated, without considering the function setting field whose switch state value in the certificate indicates the deactivated state. For example, in this embodiment, only the function setting field whose switch state value is 1 in the certificate can be considered, and the chip function corresponding to the function setting field whose switch state value is 1 can be activated, without considering the function setting field whose switch state value is 0 in the certificate.
[0116] Scenario 2: Activating and deactivating chip functions based on certificate configuration. For example, this embodiment can extract the on / off state values of each function setting field in the certificate, and configure the on / off state of the chip function corresponding to each function setting field according to the on / off state values of each function setting field. That is, this embodiment considers both activated and deactivated function setting fields in the certificate, and configures the on / off state of each chip function based on the specific on / off state values of each function setting field in the certificate. For example, for a function setting field in the certificate that indicates an activated state (e.g., a function setting field with an on / off state value of 1), this embodiment can activate the corresponding chip function; for a function setting field in the certificate that indicates a deactivated state (e.g., a function setting field with an on / off state value of 0), this embodiment can deactivate the corresponding chip function.
[0117] In the first scenario described above, we focus on the function setting field in the certificate where the switch status value indicates the active state (e.g., switch status value is 1), and activate the corresponding chip function in the function setting field, while ignoring the function setting field in the certificate where the switch status value indicates the deactivated state (e.g., switch status value is 0). Scenario 1 can be applied to the mode of adding a new activated chip function to the chip, that is, it is applicable to the incremental activation mode of chip functions. In other words, the chip can use the certificate to add a new activated chip function without changing the switch status of other chip functions, such as not considering deactivating the already activated chip functions.
[0118] For example, taking chip function 1 and chip function 2 as examples, Figure 4 An example diagram illustrating the incremental activation mode of chip functionality provided in this application embodiment is shown, such as... Figure 4As shown, assuming that the user only needs to use chip function 1 when starting to use the chip, the chip manufacturer can provide a certificate 401 to support the activation of chip function 1. The incremental activation mode based on chip function only focuses on the function setting field with a switch state value of 1. Therefore, certificate 401 can be configured to activate chip function 1 without activating other chip functions. For example, certificate 401 can be configured as FEATURE1_SETTING=1 and FEATURE2_SETTING=0. After the chip successfully imports certificate 401, since the incremental activation mode only focuses on the function setting field 1 (i.e., FEATURE1_SETTING) with a switch state value of 1 in certificate 401, chip function 1 can be activated based on certificate 401. That is, chip function 1 is configured to be in an active state, and FEATURE2_SETTING=0 in certificate 401 is ignored.
[0119] Subsequently, if the user needs to use chip function 2 again, the user can request a certificate 402 from the chip manufacturer to support the activation of chip function 2. Since the incremental activation mode of chip function only focuses on the function setting field with a switch state value of 1, the certificate 402 can be configured to activate chip function 2 without activating other chip functions. For example, the certificate 402 can be configured as FEATURE1_SETTING=0 and FEATURE2_SETTING=1. After the chip successfully imports the certificate 402, since the incremental activation mode only focuses on the function setting field 2 (i.e., FEATURE2_SETTING) with a switch state value of 1 in the certificate 402, the chip function 2 can be activated based on the certificate 402 (i.e., the chip function 2 is configured to be in an active state), and the FEATURE1_SETTING=0 in the certificate 402 is ignored, thus maintaining the original active state of chip function 1.
[0120] In scenario one, we only need to focus on newly activated chip functions without considering disabling already activated chip functions, which simplifies the configuration of chip functions.
[0121] The above scenario two comprehensively considers the on / off status values of various function setting fields in the certificate. It activates the chip function corresponding to the function setting field whose on / off status value indicates an active state (e.g., on / off status value 1), and also considers deactivating the chip function corresponding to the function setting field whose on / off status value indicates a deactivated state (e.g., on / off status value 0). This allows for the unified configuration of the on / off status of multiple chip functions in the certificate, supporting scenarios such as chip functions being activated and then deactivated, and chip functions being deactivated and then activated again. This enables precise control of the on / off status of each chip function to meet specific user needs.
[0122] For example, taking chip function 1 and chip function 2 as examples, Figure 5An exemplary diagram illustrating the activation and deactivation variations of chip functions provided in embodiments of this application is shown, such as... Figure 5 As shown, assuming that the user only needs to use chip function 1 when starting to use the chip, the chip manufacturer can provide a certificate 501 that supports activating chip function 1 and disabling chip function 2. That is, considering the on / off status values of each function setting field in the certificate, if the user only needs to use chip function 1, the on / off status value of the function setting field corresponding to chip function 1 in the corresponding certificate is 1, while the on / off status value of the function setting fields corresponding to other chip functions is 0. For example, certificate 501 can be configured as FEATURE1_SETTING=1 and FEATURE2_SETTING=0. After the chip successfully imports certificate 501, considering the on / off status values of each function setting field in certificate 501, this embodiment can activate chip function 1 based on function setting field 1 (i.e., FEATURE1_SETTING) with an on / off status value of 1 in certificate 501, and disable chip function 2 based on function setting field 2 (i.e., FEATURE2_SETTING) with an on / off status value of 0 in certificate 501.
[0123] Subsequently, if a user needs to use chip function 2 instead of chip function 1, the user can request a certificate 502 from the chip manufacturer to support the activation of chip function 2 and the deactivation of chip function 1. For example, certificate 502 can be configured as FEATURE1_SETTING=0 and FEATURE2_SETTING=1. After the chip successfully imports certificate 502, this embodiment of the application can activate chip function 2 based on the function setting field 2 (i.e., FEATURE2_SETTING) with a switch state value of 1 in certificate 502, and deactivate chip function 1 based on the function setting field 1 (i.e., FEATURE1_SETTING) with a switch state value of 0 in certificate 502.
[0124] Similarly, if a user needs to use both chip function 1 and chip function 2 simultaneously, the user can request a certificate from the chip manufacturer to support the activation of chip function 1 and chip function 2. For example, the certificate can be configured as FEATURE1_SETTING=1 and FEATURE2_SETTING=1. After the chip successfully imports the certificate, based on the function setting field 1 and function setting field 2 with a value of 1 in the certificate, the embodiment of this application can activate chip function 1 and chip function 2.
[0125] Based on the chip function configuration scheme provided in the embodiments of this application, the chip's processor firmware (such as CPU firmware) can activate the chip function (i.e., configure the chip function to be in an activated state) or deactivate the chip function (i.e., configure the chip function to be in a deactivated state) according to the certificate. In an optional implementation, the processor firmware can write the configuration value of the processor function corresponding to the function setting field into the processor's configuration register according to the on / off state value of the function setting field in the certificate, so as to control the on / off state of the hardware circuit of the processor function corresponding to the function setting field, such as determining whether the hardware circuit of the processor function corresponding to the function setting field is turned on or off. Here, the processor function can be regarded as an example of the chip function.
[0126] It should be noted that the processor's configuration register is used to store configuration information (such as configuration values) that controls the processor's hardware behavior. For example, in processors such as CPUs, the configuration information (such as configuration values) stored in the configuration register can include on / off configuration information of processor functions (such as configuration information of enabled or disabled functional units in the processor), power management configuration information, etc. Therefore, by adjusting the configuration value of the processor function corresponding to the function setting field in the processor's configuration register, the on / off state of the processor function corresponding to the function setting field can be controlled.
[0127] In an optional implementation, embodiments of this application can control the on / off state of processor functions through bit control logic in the configuration register. For example, at least one (or more) bit of the processor's configuration register can correspond to a processor function. By changing the value of the corresponding bit in the configuration register, the configuration value of the processor function in the configuration register can be changed, thereby adjusting the on / off state of the processor function's hardware circuitry. For example, the bit in the processor's configuration register corresponding to a processor function can represent a control signal or setting option for the processor function. When the bit corresponding to the processor function is set (e.g., set to 1) or cleared (e.g., cleared to 0), the hardware circuitry of the processor function can change its on / off state, such as turning it on or off. For instance, when the bit in the processor's configuration register corresponding to a certain processor function is set or cleared, the electronic signal (high-level signal or low-level signal) represented by the bit will be transmitted to the hardware circuitry of that processor function, thereby triggering the logic gate of the hardware circuitry of that processor function to adjust the on / off state of the hardware circuitry of the processor function. In a possible implementation, if the bit corresponding to the processor function in the configuration register is set to the first value (e.g., 1), the hardware circuitry of the processor function can be turned on, thereby activating the processor function, i.e., the processor function is in an active state; if the bit corresponding to the processor function in the configuration register is cleared to the zero value (e.g., 0), the hardware circuitry of the processor function can be turned off, thereby deactivating the processor function, i.e., the processor function is in a deactivated state.
[0128] Based on the above description, in an optional implementation, embodiments of this application can set configuration values in the processor's configuration register corresponding to the processor function of the function setting field according to the on / off state value of the function setting field in the certificate, so as to control the on / off state of the hardware circuit of the processor function corresponding to the function setting field. For example, for a function setting field whose on / off state value indicates an active state, a configuration value can be set in the configuration register corresponding to the processor function of the function setting field to control the hardware circuit of the corresponding processor function to be in an active state; for a function setting field whose on / off state value indicates a closed state, a configuration value can be set in the configuration register corresponding to the processor function of the function setting field to control the hardware circuit of the corresponding processor function to be in a closed state.
[0129] The above method can be applied to both Case 1 and Case 2. For example, for Case 1, this embodiment can set the first value (e.g., 1) in the bit of the processor function corresponding to the function setting field in the processor's configuration register based on the first value (e.g., 1) of the function setting field in the certificate, thereby controlling the activation of the processor function's hardware circuitry. For example, for Case 2, this embodiment can set the first value (e.g., 1) in the bit of the processor function corresponding to the function setting field in the processor's configuration register based on the first value (e.g., 1) of the function setting field in the certificate, thereby controlling the activation of the processor function's hardware circuitry; and, based on the zero value (e.g., 0) of the function setting field in the certificate, set the zero value (e.g., 0) in the bit of the processor function corresponding to the function setting field in the processor's configuration register, thereby controlling the deactivation of the processor function's hardware circuitry.
[0130] In a further optional implementation, after the chip imports the certificate and configures the on / off state of the chip function according to the certificate, the embodiments of this application can record the activated chip function in a specific data structure, and the specific data structure can be stored in the chip's non-volatile memory to ensure that after the chip is powered off and restarted, the corresponding chip function can be activated based on the activated chip function recorded in the specific data structure, so as to realize that the chip retains the activated chip function after power off and restart.
[0131] For ease of explanation, the aforementioned specific data structure can be referred to as Supported Feature data. This support data can record at least the activated chip functions, such as the feature identifiers of the activated chip functions. Furthermore, similar to the recording method of the feature setting field in a certificate, the support data can record the feature identifiers corresponding to multiple chip functions, and the on / off state of each feature identifier indicates the on / off state of the chip function. Therefore, by setting the on / off state values of the feature identifiers corresponding to the activated chip functions in the support data to indicate the active state, it is possible to record the activated chip functions in the support data.
[0132] Example, Figure 6 An exemplary diagram illustrating the format of functional support data provided in embodiments of this application is shown for reference. Figure 6 As shown, the function support data can record the function identifiers of multiple chip functions. For example, taking multiple chip functions as n chip functions, the function support data can record the function identifier FEATURE1 of chip function 1, the function identifier FEATURE2 of chip function 2, and so on, up to the function identifier FEATUREn of chip function n. For each chip function's function identifier, if the switch state value of the function identifier is the first value (e.g., 1), it indicates that the chip function is in the active state; if the switch state value of the function identifier is the zeroth value (e.g., 0), it indicates that the chip function is in the off state.
[0133] It should be noted that the function support data is recorded in the chip's non-volatile memory. This data is used to ensure that the active chip functions remain consistent with those before the power failure after the chip is powered off and restarted. It is a management method for keeping the active chip functions. On the other hand, the function setting field and its on / off status value are recorded in the certificate. This data is used to update the active and / or disabled chip functions. Therefore, the function support data and the function setting field in the certificate are used in different ways.
[0134] As an optional implementation Figure 7 An exemplary flowchart of an optional chip function configuration supporting power-down restart provided in an embodiment of this application is illustrated. This process can be executed by a chip loaded into an electronic device, specifically by the chip's processor firmware (such as CPU firmware). (Refer to...) Figure 7 The process may include the following steps.
[0135] In step S710, at least the currently active chip functions are recorded in the function support data.
[0136] In an optional implementation, after the chip imports the certificate and updates the on / off state of the chip functions according to the certificate, the processor firmware can at least record the currently active chip functions in the function support data. For example, after the certificate verification is successful, the chip imports the certificate, and configures the on / off state of the chip functions corresponding to the function setting fields according to the on / off state values in the certificate, the processor firmware can at least determine the currently active chip functions and at least record the currently active chip functions in the function support data. For example, embodiments of this application can at least record the function identifier corresponding to the currently active chip function in the function support data.
[0137] In a further optional implementation, embodiments of this application may also support recording the function identifiers corresponding to multiple chip functions of the chip, as well as the on / off state values of each function identifier, in the function support data, so as to reflect the currently activated chip function of the chip by using the on / off state values of the function identifiers in the function support data to represent the activated state of the function identifiers.
[0138] In step S711, the function support data is encrypted according to the chip key to obtain encrypted function support data.
[0139] In an optional implementation, to securely protect the function support data, the processor firmware (such as CPU firmware) can encrypt the function support data using the chip's unique chip key, resulting in encrypted function support data to protect its confidentiality.
[0140] In optional implementations, the encryption algorithm can be a symmetric encryption algorithm such as SM4.
[0141] In an optional implementation, the encryption function supports the use of a chip-unique key for the data. This chip-unique key can be a unique key generated specifically for the chip, meaning each chip possesses a unique key, and different chips have different key values. For example, the chip-unique key can be generated during chip manufacturing or during chip startup (e.g., the first time the chip is booted) using a secure key generation algorithm. The chip key can be stored in a secure storage area on the chip, which can be designed to be inaccessible or unmodifiable externally to prevent the chip key from being illegally stolen or leaked.
[0142] In step S712, the encrypted functional support data is protected for integrity, and integrity protection information is obtained.
[0143] In an optional implementation, after the function support data is encrypted, integrity protection can be applied to the encrypted function support data to generate integrity protection information, thereby preventing the data from being tampered with during storage. In an optional implementation, embodiments of this application can use a hash algorithm to calculate the hash value of the encrypted function support data, such as HMAC (Hash-based Message Authentication Code), to obtain the integrity protection information.
[0144] In step S713, the encrypted function support data and integrity protection information are written into the chip's non-volatile memory.
[0145] In a further optional implementation, integrity protection information can be added to the integrity protection field. This allows the integrity protection field with added integrity protection information, along with encrypted data, to form write data, which is then written to the chip's non-volatile memory, ensuring that the written data is not lost after power failure. Non-volatile memory refers to storage devices that retain data even after power loss, such as flash memory and non-volatile RAM.
[0146] It should be noted that steps S711 to S713 are merely optional implementations for securing the function support data and writing the secured function support data into the chip's non-volatile memory. In other words, the method of encrypting the function support data and then protecting its integrity shown in steps S711 to S713 is only an optional implementation for securing the function support data. For example, embodiments of this application can also support integrity protection of the function support data to obtain integrity protection information, and then encrypt the function support data and integrity protection information using the chip's chip key, before writing the encrypted data into the chip's non-volatile memory. Of course, securing the function support data is not limited to encryption and integrity protection; technologies such as digital signatures can also be used.
[0147] Furthermore, after the chip is powered off and restarted, the embodiments of this application can utilize the functional support data written to the chip's non-volatile memory to activate the chip's functions, so that the activated chip functions are consistent with those before the power failure.
[0148] Further integration Figure 7 As shown, in step S714, after the chip is powered off and restarted, encrypted function support data and integrity protection information are read from the chip's non-volatile memory.
[0149] In step S715, based on the read integrity protection information, the integrity of the encrypted function support data is checked, and it is determined whether the integrity check passes. If not, step S716 is executed; if yes, step S717 is executed.
[0150] In step S716, the process ends.
[0151] In step S717, the encrypted function support data is decrypted according to the chip key of the chip to obtain the decrypted function support data.
[0152] In an optional implementation, after the chip powers off and restarts, the processor firmware can read encrypted function support data and integrity protection information from non-volatile memory. Before decrypting the encrypted function support data, this embodiment can perform integrity verification on the encrypted function support data based on the read integrity protection information to determine whether the encrypted function support data has been tampered with. For example, the integrity protection information of the encrypted function support data can be recalculated (e.g., the hash value can be recalculated), and the recalculated integrity protection information can be compared with the read integrity protection information. If the comparison result is consistent, the integrity verification passes, and the encrypted function support data continues to be decrypted; if the comparison result is inconsistent, the integrity verification fails, and this embodiment can end the process.
[0153] If the integrity verification passes, the processor firmware can use the chip key to decrypt the encrypted function support data, thereby obtaining the decrypted function support data.
[0154] It should be noted that steps S715 to S717 can be considered as an optional implementation process for restoring the securely protected functional support data to obtain the functional support data. If the restoration fails, the process ends. It is understood that the method for restoring the securely protected functional support data can vary depending on the method used for security protection, and is not limited to steps S715 to S717. For example, if the security protection of the functional support data involves integrity protection before encryption, this embodiment can first decrypt the securely protected functional support data read from the chip's non-volatile memory (using the chip's chip key), then recalculate the hash value of the decrypted functional support data, compare the recalculated hash value with the decrypted hash value for integrity verification, and if the integrity verification passes, use the decrypted functional support data as the restored functional support data.
[0155] In step S718, the corresponding chip function in the chip is activated according to the activated chip function of the function support data record.
[0156] Based on the recorded functional support data, embodiments of this application can activate the active chip functions recorded in the functional support data in the chip to maintain the active chip functions consistent with those before power loss. For example, taking a processor function as an example, the configuration value of the corresponding processor function in the configuration register can be configured according to the active processor function recorded in the functional support data to activate the hardware circuit of the corresponding processor function. The relevant content of configuring the configuration value of the processor function in the configuration register can be referred to the description in the corresponding section above, and will not be elaborated here.
[0157] This application embodiment can control and manage the on / off state of chip functions through certificates. Compared with hardware-based chip function locking (such as using eFuse), this application embodiment can improve the configuration flexibility of chip functions, thereby adapting to flexible and changing user needs and providing chips with functions adapted to user requirements. Specifically, the chip functions do not need to be permanently locked at the factory using methods such as eFuse. Instead, users can update the on / off state of chip functions by importing certificates into the chip. That is, users can import certificates adapted to their needs to control the activation or deactivation of chip functions, thereby making the on / off state of chip functions flexibly adaptable to user needs.
[0158] Furthermore, users can import different certificates that support the activation of different chip functions to support various combinations of chip features. For example, chip manufacturers can provide certificates with multiple function configurations for the same chip, and users can choose to purchase one or more certificates that suit their needs to support different combinations of chip functions. Moreover, after purchasing a chip, if a user needs to update its functions, such as using a specific chip function that is not yet activated, they can purchase the corresponding certificate from the chip manufacturer. The user can then import this certificate into the chip to activate the authorized chip functions, meeting their needs for using specific chip functions.
[0159] In other words, users do not need to decide all the chip functions they need when purchasing the chip. Instead, they can purchase and activate specific chip functions according to their actual needs during subsequent use of the chip. This helps users control the cost of purchasing chips and provides a flexible and controllable way to upgrade the chip's functions.
[0160] For example, users can upgrade chip value-added functions using the solutions provided in this application. Taking the TKM function as an example, the TKM function can be implemented based on the firmware of the CPU's built-in Platform Secure Processor (PSP). That is, unlike key management implemented through a physical cryptographic card, the TKM function is integrated inside the CPU and implemented through the CPU's built-in secure processor firmware. This design tightly integrates key management with other functions of the processor, reducing the exposure of physical interfaces and thus lowering the risk of attack. It should be noted that the secure processor is a dedicated security processing unit integrated inside the CPU, responsible for handling security-sensitive tasks such as key management, encryption operations, and system startup security verification. For example, the secure processor can access all system resources, including CPU control, system memory, and peripherals. The initialization code of the secure processor is fixed inside the chip and cannot be changed. Therefore, the secure processor can use the initial code to verify the legality and integrity of subsequent code, ensuring security and reliability.
[0161] TKM (Trusted Knowledge Management) is an added-value feature of chips (such as CPU chips). If users need to use TKM, they can purchase a certificate from the chip manufacturer (such as the CPU manufacturer) that supports TKM activation. For example, TKM can correspond to a function setting field in the certificate, and the on / off state value of the function setting field corresponding to TKM in the certificate indicates the activation state (for example, if the on / off state value of the function setting field corresponding to TKM in the certificate is 1), then the certificate supports TKM activation. Thus, by importing the certificate that supports TKM activation into the chip (such as the chip's security processor), the chip can support TKM, allowing users to choose whether to use the added-value service of TKM as needed.
[0162] In a further optional implementation, this application embodiment also provides a chip function configuration device. The chip function configuration device can be considered as a functional module required by the chip (such as the chip's processor firmware) to implement the chip function configuration method provided in this application embodiment. The following description can be referred to in correspondence with the above description. It should be noted that the chip function configuration method provided in this application embodiment supports execution by the chip's processor firmware (such as CPU firmware), wherein the processor firmware is pre-written software embedded in the processor or chip's read-only memory (ROM) or other types of non-volatile memory.
[0163] As an optional implementation Figure 8 An exemplary block diagram of an optional chip function configuration device provided in an embodiment of this application is shown. This chip function configuration device can be applied to a chip, such as to the chip's processor firmware (e.g., CPU firmware). (Refer to...) Figure 8The chip function configuration device may include:
[0164] The certificate acquisition module 810 is used to acquire the certificate to be imported. The certificate includes a verification field with verification information and multiple function setting fields with switch status values configured. One of the function setting fields corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field.
[0165] The verification module 820 is used to verify whether the certificate passes based on the verification information;
[0166] The function configuration module 830 is used to import the certificate if the certificate is verified, and configure the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value of the function setting field in the certificate.
[0167] In an optional implementation, the certificate acquisition module 810 is used to acquire the certificate to be imported, including:
[0168] Select one preset certificate from multiple preset certificates of the chip; wherein, a preset certificate of the chip is pre-generated based on a preset functional requirement information of the chip, the preset functional requirement information of the chip includes the preset requirement switch states of multiple chip functions, and the preset requirement switch states of multiple chip functions indicated by different preset functional requirement information of the chip are different.
[0169] or,
[0170] Obtain the specified certificate for the chip; wherein, the specified certificate for the chip is generated based on the specified functional requirement information provided by the user, and the specified functional requirement information includes the specified on / off status of multiple chip functions specified by the user.
[0171] In an optional implementation, the on / off state of the chip function is divided into an active state and a deactivated state. Optionally, adapting to the above-described case one, this application embodiment supports an incremental activation mode for the chip function; therefore, the function configuration module 830, used to configure the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value of the function setting field in the certificate, may include:
[0172] Maintain the activated chip functions of the chip, and determine the function setting field in the certificate whose switch status value indicates the activated state, and activate the chip function corresponding to the function setting field whose switch status value indicates the activated state.
[0173] Optionally, adapting to the second scenario above, this embodiment of the application can comprehensively consider the on / off state values of each function setting field in the certificate; thus, the function configuration module 830, used to configure the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value of the function setting field in the certificate, may include:
[0174] Determine the function setting field in the certificate whose switch status value indicates the active state, and the function setting field whose switch status value indicates the closed state;
[0175] Activate the chip function corresponding to the function setting field whose switch status value indicates the active state, and deactivate the chip function corresponding to the function setting field whose switch status value indicates the deactivated state.
[0176] In an optional implementation, the function configuration module 830, used to activate the chip function corresponding to the function setting field whose switch state value indicates the active state, may include:
[0177] Set the on / off state of the chip function corresponding to the function setting field with the on / off state value of the first value to the active state. The on / off state value of the function setting field is the first value, which means that the corresponding chip function is active.
[0178] In an optional implementation, the function configuration module 830 is used to disable the chip function corresponding to the function setting field whose switch state value indicates an off state, including:
[0179] Set the switch state of the chip function corresponding to the function setting field with a switch state value of zero to the off state. The switch state value of the function setting field is zero, which means that the corresponding chip function is off.
[0180] In an optional implementation, the chip's processor configuration register has bits corresponding to processor functions, and at least one bit of the configuration register corresponds to a processor function; wherein, the value of the bit in the configuration register corresponding to the processor function is used to control the on / off state of the hardware circuitry of the processor function. Therefore, as an optional implementation, the function configuration module 830, for setting the on / off state of the chip function corresponding to the function setting field with a first on / off state value to an active state, may include:
[0181] For a function setting field with a switch state value of the first value, the corresponding bit in the configuration register corresponding to the processor function of the function setting field is set to the first value, so as to activate the hardware circuit of the processor function corresponding to the function setting field.
[0182] As an optional implementation, the function configuration module 830, used to set the switch state of the chip function corresponding to the function setting field with a switch state value of zero to the off state, may include:
[0183] For a function setting field with a switch state value of zero, the corresponding bit in the configuration register corresponding to the processor function of the function setting field is set to the zero value to control the hardware circuit of the processor function corresponding to the function setting field to be in the off state.
[0184] In an optional implementation, the verification field containing verification information includes: a chip identifier field containing chip identification information, and a certificate signature field containing certificate signature information, wherein the certificate signature information is a digital signature of a certificate obtained using the chip manufacturer's private key. Optionally, the verification module 820, used to verify whether the certificate passes based on the verification information, may include:
[0185] The chip manufacturer's public key is used to verify whether the certificate signature information is valid;
[0186] If the verification of the certificate signature information fails, then the verification of the certificate fails.
[0187] If the certificate signature information is verified, then check whether the chip identification information matches the chip.
[0188] If the chip identification information does not match the chip, the certificate verification fails.
[0189] If the chip identification information matches the chip, the certificate is verified.
[0190] In a further optional implementation, the embodiments of this application support the recovery of chip function after a power outage and restart. As an optional implementation, combined with... Figure 8 The chip function configuration device may also include:
[0191] The storage module 840 is used to record at least the currently active chip function in the function support data after the function configuration module 830 configures the on / off state of the chip function corresponding to the function setting field in the chip; to perform security protection on the function support data, obtain the security-protected function support data, and write the security-protected function support data into the chip's non-volatile memory;
[0192] The recovery module 850 is used to read the function support data after the chip is powered off and restarted from the non-volatile memory; restore the function support data after the power protection to obtain the function support data; and activate the corresponding chip function in the chip according to the activated chip function recorded in the function support data, so as to keep the activated chip function in the chip consistent with that before the power failure.
[0193] In an optional implementation, the storage module 840 is used to securely protect the function support data. The securely protected function support data may include:
[0194] Based on the chip key, the function support data is encrypted to obtain encrypted function support data;
[0195] The encryption function supports data integrity protection, resulting in integrity protection information.
[0196] The encrypted functional support data and the integrity protection information together form the securely protected functional support data.
[0197] In an optional implementation, the recovery module 850, used to read the protected functional support data from non-volatile memory, may include:
[0198] Read encrypted functional support data and integrity protection information from non-volatile memory.
[0199] In an optional implementation, the recovery module 850 is used to recover the function support data after security protection, and the obtained function support data includes:
[0200] Based on the read integrity protection information, perform integrity verification on the encrypted functional support data;
[0201] If the integrity verification passes, the encrypted function support data is decrypted based on the chip key to obtain the decrypted function support data.
[0202] This application also provides a chip that may include processor firmware (such as CPU firmware), which can be configured to execute the chip function configuration method provided in this application. For example, the processor firmware can be loaded with the chip function configuration device provided in this application to execute the chip function configuration method provided in this application.
[0203] This application also provides a storage medium that can store computer instructions. When these computer instructions are executed (e.g., when the computer instructions are executed by a processor), the chip function configuration method provided in this application is implemented. For example, the aforementioned computer instructions may be computer instructions of the processor firmware, which can implement the chip function configuration method provided in this application by executing the aforementioned computer instructions.
[0204] This application also provides a computer program product, such as processor firmware, which includes computer instructions. When the computer instructions are executed (e.g., when the computer instructions are executed by a processor), the chip function configuration method provided in this application is implemented.
[0205] In a further optional implementation, this application embodiment also provides a certificate generation apparatus, which can be regarded as a functional module required by the manufacturer's equipment to implement the certificate generation method provided in this application embodiment. The following description can be referred to in correspondence with the above description.
[0206] As an optional implementation Figure 9 An exemplary block diagram of an optional certificate generation apparatus provided in an embodiment of this application is shown. This certificate generation apparatus can be applied to vendor equipment. (Refer to...) Figure 9 The certificate generation device may include:
[0207] Functional requirement determination module 910 is used to determine the functional requirement information of the chip, the functional requirement information including the on / off states of multiple chip functions;
[0208] The function setting field configuration module 920 is used to configure the switch status values of multiple function setting fields of the certificate according to the switch status requirements of multiple chip functions, so that the switch status values of multiple function setting fields correspond to the switch status requirements of multiple chip functions, wherein one function setting field corresponds to one chip function.
[0209] The verification field configuration module 930 is used to determine the verification information of the chip and write the verification information into the verification field of the certificate.
[0210] In an optional implementation, the functional requirement determination module 910 is used to determine the functional requirement information of the chip, including:
[0211] From a plurality of preset functional requirement information pre-set in the chip, determine any one preset functional requirement information; wherein, a preset functional requirement information of the chip includes the preset requirement switch states of multiple chip functions, the preset functional requirement information of the chip indicates different preset requirement switch states of multiple chip functions, and a preset functional requirement information of the chip corresponds to the generation of a preset certificate of the chip.
[0212] or,
[0213] Determine the specified functional requirements information provided by the user, which includes the specified on / off states of multiple chip functions specified by the user; wherein, the specified functional requirements information corresponds to the specified certificate for the generated chip, and the specified functional requirements information is carried in the user requirement information provided by the user.
[0214] In an optional implementation, the chip verification information includes: chip identification information and certificate signature information; the certificate verification fields include: a chip identification field and a certificate signature field. Optionally, the verification field configuration module 930 is used to determine the chip verification information and write the verification information into the certificate verification fields, including:
[0215] Determine the chip identification information and write it into the chip identification field of the certificate;
[0216] Additionally, based on the chip identification information written in the chip identification field of the certificate and the on / off status values of multiple function setting fields, the certificate signature information is determined using the chip manufacturer's private key, and the certificate signature information is written into the certificate signature field of the certificate.
[0217] In an optional implementation, the verification field configuration module 930 is used to determine the chip identification information, including:
[0218] If the functional requirements information of the chip is the preset functional requirements information, then the chip identification information is determined during chip manufacturing.
[0219] If the chip's functional requirements information is specified functional requirements information, then the chip identification information provided by the user is determined from the user requirements information provided by the user.
[0220] In an optional implementation, the on / off state value of the function setting field is divided into a first value and a zero value; wherein, the required on / off state of the chip function corresponding to the function setting field with the first value is active, and the required on / off state of the chip function corresponding to the function setting field with the zero value is closed.
[0221] This application also provides a vendor device that can implement the certificate generation method provided in this application through a software method. For example, the vendor device may include a memory and a processor. The memory stores computer instructions, and the processor calls the computer instructions stored in the memory to execute the certificate generation method provided in this application.
[0222] This application also provides a storage medium that can store computer instructions, which, when executed (e.g., when executed by a processor), implement the certificate generation method provided in this application.
[0223] This application also provides a computer program product, including computer instructions, which, when executed (e.g., when executed by a processor), implement the certificate generation method provided in this application.
[0224] The foregoing describes multiple embodiment schemes provided by the embodiments of this application. The optional methods described in each embodiment scheme can be combined and cross-referenced with each other without conflict, thereby extending to a variety of possible embodiment schemes. These can all be considered as the embodiment schemes disclosed and published by the embodiments of this application.
[0225] While the embodiments disclosed above are described in this application, this application is not limited thereto. Any person skilled in the art can make various modifications and alterations without departing from the spirit and scope of this application; therefore, the scope of protection of this application should be determined by the scope defined in the claims.
Claims
1. A chip function configuration method, characterized in that, Applied to a chip, the method includes: Obtain the certificate to be imported. The certificate includes a verification field containing verification information and multiple function setting fields configured with switch status values. One of the function setting fields corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field. Based on the verification information, verify whether the certificate passes. If the certificate is verified successfully, the certificate is imported, and the on / off state of the chip function corresponding to the function setting field in the certificate is configured according to the on / off state value.
2. The method according to claim 1, characterized in that, The process of obtaining the certificate to be imported includes: Select one preset certificate from multiple preset certificates of the chip; wherein, a preset certificate of the chip is pre-generated based on a preset functional requirement information of the chip, the preset functional requirement information of the chip includes the preset requirement switch states of multiple chip functions, and the preset requirement switch states of multiple chip functions indicated by different preset functional requirement information of the chip are different. or, Obtain the specified certificate for the chip; wherein, the specified certificate for the chip is generated based on the specified functional requirement information provided by the user, and the specified functional requirement information includes the specified on / off status of multiple chip functions specified by the user.
3. The method according to claim 1, characterized in that, The chip function's on / off state is divided into an active state and a deactivated state; configuring the on / off state of the chip function corresponding to the function setting field in the certificate according to the on / off state value includes: Maintain the activated chip functions of the chip, and determine the function setting field in the certificate whose switch status value indicates the activated state, and activate the chip function corresponding to the function setting field whose switch status value indicates the activated state.
4. The method according to claim 1, characterized in that, The step of configuring the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value in the function setting field in the certificate includes: Determine the function setting field in the certificate whose switch status value indicates the active state, and the function setting field whose switch status value indicates the closed state; Activate the chip function corresponding to the function setting field whose switch status value indicates the active state, and deactivate the chip function corresponding to the function setting field whose switch status value indicates the deactivated state.
5. The method according to claim 4, characterized in that, Activating the chip function corresponding to the function setting field whose switch state value indicates the active state includes: Set the on / off state of the chip function corresponding to the function setting field with the on / off state value of the first value to the active state. The on / off state value of the function setting field is the first value, which means that the corresponding chip function is active. The step of disabling the chip function corresponding to the function setting field whose switch state value indicates an off state includes: Set the switch state of the chip function corresponding to the function setting field with a switch state value of zero to the off state. The switch state value of the function setting field is zero, which means that the corresponding chip function is off.
6. The method according to claim 5, characterized in that, The processor configuration register of the chip has bits corresponding to processor functions, and at least one bit of the configuration register corresponds to a processor function; wherein, the value of the bit in the configuration register corresponding to the processor function is used to control the switching state of the hardware circuit of the processor function. Setting the switch state of the chip function corresponding to the function setting field with the switch state value as the first value to the active state includes: For a function setting field with a switch state value of the first value, the first value is set in the bit corresponding to the processor function in the configuration register that corresponds to the function setting field, so as to control the hardware circuit of the processor function corresponding to the function setting field to be in an active state. Setting the switch state of the chip function corresponding to the function setting field with a switch state value of zero to the off state includes: For a function setting field with a switch state value of zero, the corresponding bit in the configuration register corresponding to the processor function of the function setting field is set to the zero value to control the hardware circuit of the processor function corresponding to the function setting field to be in the off state.
7. The method according to claim 1, characterized in that, The verification field containing verification information includes: a chip identifier field containing chip identification information and a certificate signature field containing certificate signature information, wherein the certificate signature information is a digital signature of a certificate obtained using the chip manufacturer's private key; The step of verifying whether the certificate passes based on the verification information includes: The chip manufacturer's public key is used to verify whether the certificate signature information is valid; If the verification of the certificate signature information fails, then the verification of the certificate fails. If the certificate signature information is verified, then check whether the chip identification information matches the chip. If the chip identification information does not match the chip, the certificate verification fails. If the chip identification information matches the chip, the certificate is verified.
8. The method according to any one of claims 1-7, characterized in that, Also includes: After configuring the on / off status of the chip function corresponding to the function setting field in the chip configuration, at least the currently active chip function should be recorded in the function support data; The function support data is protected to obtain the protected function support data, and the protected function support data is written into the chip's non-volatile memory. After the chip powers off and restarts, it reads the function support data after security protection from the non-volatile memory; The function support data is restored after security protection to obtain the function support data. Based on the activated chip functions recorded in the functional support data log, the corresponding chip functions in the chip are activated to maintain the activated chip functions consistent with those before power loss.
9. The method according to claim 8, characterized in that, The security protection of the functional support data, resulting in the securely protected functional support data, includes: Based on the chip key, the function support data is encrypted to obtain encrypted function support data; The encryption function supports data integrity protection, resulting in integrity protection information. The encrypted functional support data and the integrity protection information together form the securely protected functional support data. The data for reading the security-protected function support from the non-volatile memory includes: Read encrypted functional support data and integrity protection information from non-volatile memory; The process of restoring the function support data after security protection includes obtaining the following function support data: Based on the read integrity protection information, perform integrity verification on the encrypted functional support data; If the integrity verification passes, the encrypted function support data is decrypted based on the chip key to obtain the decrypted function support data.
10. A certificate generation method, characterized in that, Applied to manufacturer equipment, the method includes: Determine the functional requirements information of the chip, which includes the on / off states of multiple chip functions; Based on the required on / off states of multiple chip functions, configure the on / off state values of multiple function setting fields in the certificate so that the on / off state values of multiple function setting fields correspond to the required on / off states of multiple chip functions, wherein one function setting field corresponds to one chip function. Determine the chip's verification information and write it into the certificate's verification field.
11. The method according to claim 10, characterized in that, The functional requirements information for determining the chip includes: From a plurality of preset functional requirement information pre-set in the chip, determine any one preset functional requirement information; wherein, a preset functional requirement information of the chip includes the preset requirement switch states of multiple chip functions, the preset functional requirement information of the chip indicates different preset requirement switch states of multiple chip functions, and a preset functional requirement information of the chip corresponds to the generation of a preset certificate of the chip. or, Determine the specified functional requirements information provided by the user, which includes the specified on / off states of multiple chip functions specified by the user; wherein, the specified functional requirements information corresponds to the specified certificate for the generated chip, and the specified functional requirements information is carried in the user requirement information provided by the user.
12. The method according to claim 11, characterized in that, The chip's verification information includes: chip identification information and certificate signature information; the certificate's verification fields include: chip identification field and certificate signature field. The process of determining the chip's verification information and writing the verification information into the certificate's verification field includes: Determine the chip identification information and write it into the chip identification field of the certificate; Additionally, based on the chip identification information written in the chip identification field of the certificate and the on / off status values of multiple function setting fields, the certificate signature information is determined using the chip manufacturer's private key, and the certificate signature information is written into the certificate signature field of the certificate.
13. The method according to claim 12, characterized in that, The chip identification information for determining the chip includes: If the functional requirements information of the chip is the preset functional requirements information, then the chip identification information is determined during chip manufacturing. If the chip's functional requirements information is specified functional requirements information, then the chip identification information provided by the user is determined from the user requirements information provided by the user.
14. The method according to any one of claims 10-13, characterized in that, The on / off state values of the function setting field are divided into a first value and a zero value; wherein, the chip function required to be switched on / off is active when the function setting field with a switch state value of the first value is active, and the chip function required to be switched on / off is closed when the function setting field with a switch state value of the zero value is closed.
15. A chip function configuration device, characterized in that, include: The certificate acquisition module is used to acquire the certificate to be imported. The certificate includes a verification field containing verification information and multiple function setting fields configured with switch status values. One of the function setting fields corresponds to a chip function, and the switch status value of the function setting field indicates the switch status of the chip function corresponding to the function setting field. The verification module is used to verify whether the certificate passes based on the verification information. The function configuration module is used to import the certificate if the certificate is verified, and configure the on / off state of the chip function corresponding to the function setting field in the chip according to the on / off state value of the function setting field in the certificate.
16. A certificate generation device, characterized in that, include: A functional requirement determination module is used to determine the functional requirement information of the chip, which includes the on / off states of multiple chip functions. The function setting field configuration module is used to configure the on / off state values of multiple function setting fields of the certificate according to the required on / off state of multiple chip functions, so that the on / off state values of multiple function setting fields correspond to the required on / off state of multiple chip functions, wherein one function setting field corresponds to one chip function. The verification field configuration module is used to determine the chip's verification information and write the verification information into the certificate's verification field.
17. A chip, characterized in that, Includes processor firmware, which is configured to perform the chip function configuration method as described in any one of claims 1-9.
18. A manufacturer's equipment, characterized in that, The system includes a memory and a processor, the memory storing computer instructions, and the processor invoking the computer instructions stored in the memory to execute the certificate generation method as described in any one of claims 10-14.
19. A storage medium, characterized in that, The storage medium stores computer instructions, which, when executed, implement the chip function configuration method as described in any one of claims 1-9, or the certificate generation method as described in any one of claims 10-14.
20. A computer program product, characterized in that, It includes computer instructions, which, when executed, implement the chip function configuration method as described in any one of claims 1-9, or the certificate generation method as described in any one of claims 10-14.